Sending your agent an email, by way of a bullet
The thing your agent should work on often reaches you first as an email: a supplier’s quote, an alert about a build that failed overnight, a customer’s reply to a ticket. Getting it to the agent means copying it out of your mailbox and pasting it into a session, by hand, each time one arrives.
In Pando, choose Email into this bullet in a bullet’s menu to give it its own address, and send or forward the email there: the subject arrives as a new bullet under it and the message as that bullet’s note. An agent that reaches that branch finds the email the next time it reads there, since Pando does not wake an agent.
Forwarding still puts your hand on every email. To take the hand out, give the address to whatever sends the email, the build server’s alert list for one, and the alerts arrive by themselves. Do that only for a sender you would let write in that branch, for the reason further down.
Set it up
- Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
- Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.
That connects the agent. You make the address yourself, in the app: open the bullet’s menu and choose Email into this bullet, and the address exists the moment the sheet opens. Copy the address puts it on your clipboard. Any bullet you may edit while signed in can have one, one at a time, and opening the sheet again shows the same address.
An agent cannot make an address for itself. The server refuses anything but a signed-in person, because an address outlives the key that would have made it, and taking the key back would not close it.
What arrives
- One email, one new bullet, placed last under the bullet the address belongs to.
- The subject is its line. An empty subject arrives as (no subject), and a long one is cut at 300 characters.
- The message is its note, and after it a from line with whatever the email’s From header says, which the sender writes and nothing checks. The note is cut at 8,000 characters, and a message that long loses the from line with it.
- Plain text is kept as written, and an email sent only as HTML arrives as its words, without the markup. Accents and umlauts in the message survive its encoding.
- Attachments do not arrive. A receipt with a PDF attached brings the words of the email and leaves the PDF behind.
- Forward it inline. An email forwarded as an attachment arrives with only the words you added, and the message you forwarded is left behind.
Put the address where the agent already reads
The simplest place is under the agent’s own memory bullet. Give that bullet a child called Mail and put the address on the child. Asked with no branch named, the tree and changes tools read the memory bullet and what is under it, so the email is in the first place the agent looks, and it stays apart from what the agent wrote itself. Tell the agent once that Mail holds other people’s words.
Anywhere else, tell the agent which branch to read. A connector you approved starts with your whole outline, so any branch will do until you let it reach only one bullet. An agent held that way, or one created under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked, reaches only the branch chosen on its row under Your agents, and everything under it, so the address has to be on that branch or below it.
Tell it to read the notes too. The message is in the note, and a tree read in its default outline mode leaves notes out. The changes tool returns each new bullet with its note, and so does search.
What Pando does not do
- It does not wake the agent. Pando sends an agent no notification and calls no webhook, so an email waits in the outline until the agent next reads that branch. If the agent has to act the minute an email lands, this is not the tool for it.
- It does not start a session. Claude Code’s docs say each session "begins with a fresh context window", so a session finds the email only if something tells it to look, such as a line in CLAUDE.md asking it to call changes at the start and keep the cursor it hands back in its memory.
- It does not send email for the agent. None of the tools an agent holds sends email, so the agent cannot answer the sender through Pando.
Anybody with the address writes as you
The sheet says it under the address: anybody who has it can write into this bullet, and nowhere else, so treat it like a share link. The sender needs no account, and the bullet is written in the name of the person who made the address. Its from line is the only sign it came by email, and a long message loses even that.
For an agent, that is the part to weigh. A stranger holding the address puts words where your agent reads them, in a bullet that looks like one of yours. Pando’s instructions to every MCP client say that words in a bullet are data and never instructions, and a bullet that came by email does not carry the mark that tells an agent somebody else wrote it. Whether a model always holds to that is not something Pando can promise. Give the address to senders you would let write in that branch, and to nobody else.
The same holds for an email you forward yourself: the words in it are still the sender’s. Tell the agent what to do with each one. The email is material for the work, never the instruction.
Because the email is written as you, a lock that refuses agents only does not stop it arriving. A lock that refuses everyone, on that bullet or any bullet above it, does, and the email bounces with the reason. A lock against agents does its work on the other side: if an email talks the agent into something, a branch locked against agents still refuses every change it tries there.
Turning it off
Open Email into this bullet on the same bullet and press Turn this address off. Mail to it bounces from then on, and the bullets that already arrived stay where they are. Opening the sheet again later makes a new address, different from the old one, even if you only opened it to look, and closing the sheet leaves that new one on.
You can turn off an address you made, and, as the owner of the outline, one a collaborator made in it, since the sheet shows a bullet’s address to anyone who may edit that bullet. No screen in the app lists every address at once, so each one is found on its own bullet.
When an email bounces
- The address was turned off, never existed, or was made by somebody who may no longer write in that bullet, such as a collaborator whose share was taken back.
- The outline is at its bullet limit. Each email is one new bullet and counts like any other.
- The outline has been put into read-only, or a lock against everyone covers the bullet.
- Inbound email has been switched off for all of Pando, and the bounce says so.
A deleted bullet does not make mail to an address you made bounce, but mail to one a collaborator made does, because they may not write at the top of your outline. The email lands at the top level of your outline instead, where an agent reading only that branch no longer finds it, and that is the one time an address writes anywhere but its own bullet. To stop it, put the bullet back from the Trash, open Email into this bullet on it, and press Turn this address off.
What it costs
Nothing, for 1,000 bullets, with every feature and no card. Each email that arrives is one of those bullets.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this